frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console

https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild
19•uvuv•1h ago

Comments

chuckadams•23m ago
Breaking this down, several of AWS's core repos like the JS SDK use an allowlist of which contributor ids can run workflow actions in their PRs. The list was a regex, contained several short ids, and wasn't anchored with ^$, so if it allowed user 12345, then any userid containing 12345 could run their own actions on the PR, including one that exfiltrated access tokens. So they spammed GH with user creation requests, got an id that matched, and they were in like Flynn.

Said tokens didn't have admin access, but had enough privileges to invite other users to become full admins. Not sure if they were rotated, but github tokens are usually long-lived, like up to a year. Hey, isn't AWS the one always lecturing us to use temporary credentials? To be fair, AWS did more than just fix the regex, they introduced an "approve workflow run" UI unto the PR process that I think GH is also using now (not sure about that).

Open source MySQL repository has no commits in more than three months

https://devclass.com/2026/01/13/open-source-mysql-repository-has-no-commits-in-more-than-three-mo...
1•firesteelrain•53s ago•0 comments

Thumby, a Tiny Playable Keychain

https://thumby.us/
1•tosh•2m ago•0 comments

Decreasing human body temperature in United States since Industrial Revolution

https://elifesciences.org/articles/49555
2•paulpauper•4m ago•0 comments

Astronauts splash down to Earth after medical evacuation from space station

https://www.bbc.com/news/articles/c205r8n0276o
1•reconnecting•4m ago•1 comments

OpenAI Codex Zoom Event – 10xing Eng Velocity

https://bvp.zoom.us/webinar/register/WN_bul7bYg6RcCXBuxl30KwRA#/registration
1•bnagda•5m ago•1 comments

Show HN: Skillthis.ai – Generate AI skills using Claude's best practices

https://skillthis.ai
1•barefootsanders•5m ago•1 comments

Burn 0.20.0: Unifying CPU and GPU Kernels with CubeCL

https://burn.dev/blog/release-0.20.0/
1•dabinat•6m ago•0 comments

Visualizing and managing Pipewire audio graphs from Emacs

https://sachachua.com/blog/2026/01/visualizing-and-managing-pipewire-audio-graphs-from-emacs/
1•JNRowe•6m ago•0 comments

Archaeologists uncover Victorian children's schoolwork in east London

https://www.ianvisits.co.uk/articles/archaeologists-uncover-victorian-childrens-schoolwork-in-eas...
1•7777777phil•6m ago•0 comments

UK offshore wind prices come in 40% cheaper than gas in record auction

https://electrek.co/2026/01/14/uk-offshore-wind-record-auction/
2•doener•8m ago•0 comments

Show HN: I built an 11MB offline PDF editor because mobile Acrobat is 500MB

https://revpdf.com/
2•pawandeepsingh•8m ago•1 comments

How to Bounce Postal Mail

https://blog.zgp.org/how-to-bounce-postal-mail/
2•speckx•9m ago•0 comments

Ratelimit is a Feature, not a constraint

https://dantelex.com/blog/ratelimits-are-features
1•lexokoh•10m ago•0 comments

Show HN: Pageplane – Copy and Paste Deployments for HTML Apps

https://pageplane.app
1•christoff12•12m ago•0 comments

AI Physicians at Last

https://marginalrevolution.com/marginalrevolution/2026/01/ai-physicians-at-last.html
1•paulpauper•13m ago•0 comments

China's mighty green tech sector still has stubborn weak points

https://www.ft.com/content/d67c3011-646e-4363-a83d-1e9d3f23c9a0
1•paulpauper•14m ago•0 comments

Show HN: Tusk Drift – Turn production traffic into API tests

https://github.com/Use-Tusk/tusk-drift-cli
4•jy-tan•14m ago•0 comments

Ask HN: For those of you building AI agents, how have you made them faster?

1•arkmm•16m ago•0 comments

Are open source maintainers going to be the main sufferers from LLM

https://github.com/ghostty-org/ghostty/pull/10205
1•jemiluv8•16m ago•2 comments

You can now import data from CSV files without Power Query

https://www.neowin.net/news/good-news-for-excel-users-you-can-now-import-data-from-csv-files-with...
1•bundie•16m ago•0 comments

Musk Praises Anthropic's Claude for Coding Lead over Grok 4.20

https://twitter.com/elonmusk/status/2011699395717447749
1•sh_tomer•17m ago•0 comments

DriftMind – Anomaly detection and forecasting for Excel users (no signup)

https://thingbook.io/csvanalysis.html
2•romanfll•17m ago•3 comments

Show HN: Munimet.ro – ML-based status page for the local subways in SF

https://munimet.ro/
1•MrEricSir•17m ago•0 comments

Show HN: I built a self-hosted video search tool because Google's API was $$$

1•iliashad•17m ago•0 comments

TranslateGemma: A new suite of open translation models

https://blog.google/innovation-and-ai/technology/developers-tools/translategemma/
1•kerim-ca•18m ago•0 comments

Vibe Mapping – Google's Antigravity is pretty damn amazing

https://flower.codes/2026/01/15/antigravity.html
1•speckx•19m ago•0 comments

Interview with Todd Green, head of the company that created 'Candy Crush'

https://english.elpais.com/technology/2025-12-27/todd-green-head-of-the-company-that-created-cand...
1•PaulHoule•19m ago•0 comments

Show HN: Google Flights TUI

https://github.com/spacegauch0/flights-scraper-effect
1•dperalta•19m ago•0 comments

Looking at a Real Fake Raspberry Pi RP2040 Board

https://hackaday.com/2026/01/15/looking-at-a-real-fake-raspberry-pi-rp2040-board/
1•hpb42•20m ago•0 comments

Show HN: I have build a free random code generator (250k codes/batch)

https://codito.io/free-random-code-generator/
1•tomge•20m ago•1 comments